User Tools

Site Tools


computing:onlyoffice

This is an old revision of the document!



  • onlyoffice
  • Jonathan Haack
  • Haack's Networking
  • webmaster@haacksnetworking.org

OnlyOffice


Introduction

This tutorial is for Debian users who wish to spin up an Only Office container using podman. It presumes you have a Cockpit container VM/host setup already. If not, head over to Cockpit before you start here. Once podman is setup and you have a dedicated rootless user, you can proceed. To begin with, let's setup a directory for this container and generate our jwt secret:

1. Directories and secret (worker)

mkdir -p ~/onlyoffice/{data,logs,lib,db}
umask 077
openssl rand -hex 32 | tee ~/onlyoffice/jwt.secret
chmod 600 ~/onlyoffice/jwt.secret

Placeholder used below:

JWT_SECRET=replace-with-your-jwt-secret

2. Quadlet

systemctl --user disable --now container-onlyoffice.service 2>/dev/null || true
rm -f ~/.config/systemd/user/container-onlyoffice.service
podman rm -f onlyoffice

mkdir -p ~/.config/containers/systemd
cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF'
[Container]
ContainerName=onlyoffice
Image=docker.io/onlyoffice/documentserver:latest
PublishPort=127.0.0.1:8082:80
Environment=JWT_ENABLED=true
Environment=JWT_SECRET=replace-with-your-jwt-secret
Environment=JWT_HEADER=Authorization
Environment=ALLOW_PRIVATE_IP_ADDRESS=false
Volume=/home/worker/onlyoffice/logs:/var/log/onlyoffice:Z
Volume=/home/worker/onlyoffice/data:/var/www/onlyoffice/Data:Z
Volume=/home/worker/onlyoffice/lib:/var/lib/onlyoffice:Z
Volume=/home/worker/onlyoffice/db:/var/lib/postgresql:Z
Volume=/home/worker/podman-local/volumes/84a360c1a5dd357b0cfe5af71a59f7338eeca694336b1ea8bef5d5c41fe7deb7/_data:/usr/share/fonts/truetype/custom:Z
PodmanArgs=--cpus=4 --memory=8g
[Service]
Restart=always
TimeoutStopSec=120
[Install]
WantedBy=default.target
EOF

systemctl --user daemon-reload
systemctl --user reset-failed container-onlyoffice.service
systemctl --user start container-onlyoffice.service

WantedBy=default.target starts it. Do not systemctl enable a Quadlet unit. Do not podman generate systemd. Drop the fonts Volume= line if you have no custom fonts. JWT header must be Authorization, not AuthorizationJwt.

3. Verify

sleep 90
systemctl --user is-active container-onlyoffice.service
podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}'
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
podman exec onlyoffice supervisorctl status

Expect active, cpus=4000000000, memory=8589934592, HTTP 200, and ds:converter / ds:docservice RUNNING. First start takes about 90 seconds.

4. Upgrade script

/usr/local/bin/upgrade-onlyoffice.sh. A tag change is an edit to Image= in the .container file before daemon-reload. The script does not recreate the unit.

#!/bin/bash
set -euo pipefail

podman pull docker.io/onlyoffice/documentserver:latest

systemctl --user stop container-onlyoffice.service
systemctl --user daemon-reload
systemctl --user reset-failed container-onlyoffice.service
systemctl --user start container-onlyoffice.service

sleep 90
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck

Run it as worker:

su - worker -c '/bin/bash /usr/local/bin/upgrade-onlyoffice.sh'

Do not sudo -u worker. That drops the session bus.

5. Apache reverse proxy (root)

a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl

/etc/apache2/sites-available/files.haacksnetworking.org.conf:

<VirtualHost *:80>
    ServerName files.haacksnetworking.org
    RewriteEngine On
    RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>

<VirtualHost *:443>
    ServerName files.haacksnetworking.org
    SSLEngine on
    SSLCertificateFile /etc/letsencrypt/live/files.haacksnetworking.org/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/files.haacksnetworking.org/privkey.pem
    Include /etc/letsencrypt/options-ssl-apache.conf
    SetEnvIf Host "^(.*)$" THE_HOST=$1
    RequestHeader setifempty X-Forwarded-Proto "https"
    RequestHeader setifempty X-Forwarded-Host %{THE_HOST}e
    ProxyAddHeaders Off
    ProxyPreserveHost On
    RewriteEngine On
    RewriteCond %{HTTP:Upgrade} websocket [NC]
    RewriteCond %{HTTP:Connection} upgrade [NC]
    RewriteRule ^/?(.*) "ws://127.0.0.1:8082/$1" [P,L]
    ProxyPass / http://127.0.0.1:8082/
    ProxyPassReverse / http://127.0.0.1:8082/
    ErrorLog ${APACHE_LOG_DIR}/onlyoffice-error.log
    CustomLog ${APACHE_LOG_DIR}/onlyoffice-access.log combined
</VirtualHost>
a2ensite files.haacksnetworking.org.conf
apache2ctl configtest && systemctl reload apache2
curl -sI https://files.haacksnetworking.org/healthcheck

6. Nextcloud

Admin → ONLYOFFICE:

JWT header must be Authorization.

Facts

— oemb1905 2026/10/10 03:15

computing/onlyoffice.1791602341.txt.gz · Last modified: by oemb1905